ICASSP 2023accepted0 citations

APGP: Accuracy-Preserving Generative Perturbation for Defending Against Model Cloning Attacks

Anda Cheng, Jian Cheng

Abstract

Well-trained Deep Neural Networks (DNNs) are valuable intellectual properties. Recent studies show that adversaries only with black-box query access can steal the functionality of DNNs by using knowledge distillation (KD) techniques. In this paper, we propose a novel formulation to defend against model cloning attacks. Then we implement our defense as a plug-and-play generative perturbation model, dubbed as Accuracy-Preserving Generative Perturbation (APGP). Our method is the first to effectively defend against KD-based model cloning without damaging model accuracy. Numerous experiments demonstrate the effectiveness of our defense across different datasets and DNN model cloning attacks, and the advances compared to existing methods.

BibTeX
@inproceedings{icassp2023_apgpaccuracypres,
  title = {APGP: Accuracy-Preserving Generative Perturbation for Defending Against Model Cloning Attacks},
  author = {Anda Cheng and Jian Cheng},
  booktitle = {ICASSP 2023},
  year = {2023}
}